PT-2026-95002 · Mport · Mport

·

CVE-2026-54577

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The audit command in mport/mport.c incorrectly handles argument parsing. It computes option-adjusted local argv and local argc values but passes the original argument entry to the audit package() function. If an option like -r is used before a package name, the stale optind state and unadjusted argument may lead the system to audit the option token instead of the intended package. This results in false-negatives, potentially leaving vulnerable packages unidentified.
Recommendations Update to version 2.7.8.

Exploit

Fix

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54577
GHSA-H3M9-VJ4V-C35H

Affected Products

Mport